Skip to content
Beats in Brief

Beats in Brief

Latest & Breaking News From India and The World

Primary Menu
  • Explainers
  • Business
  • Defence
  • Infrastructure
  • Tech
  • About Us
  • Editorial Policy
  • Home
  • Explainers
  • Tech

What is Anthropic’s Project Glasswing: A Model Too Dangerous To Be Released Without Strict Cybersecurity?

BRIEF: Anthropic launched Project Glasswing with a USD 104 million commitment, giving critical infrastructure companies access to a frontier AI model it considers too dangerous for public release. A US export control order on June 12 then blocked all foreign nationals from the model, locking Indian entities out mid-programme.
Dipanshu Chaturvedi June 17, 2026
3298

Claude Mythos exposes system vulnerabilities that traditional cybersecurity scans fail to recognize.

NEW DELHI: On April 7 2026, Anthropic launched Project Glasswing, a controlled-access cybersecurity programme giving critical infrastructure companies access to Claude Mythos Preview a frontier AI model the company considers too dangerous for public release committing USD 104 million to help defenders find and fix vulnerabilities before the capability spreads beyond its control.

What the Programme Is and Who Is In It

The initiative launched with 12 founding consortium partners: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks, alongside Anthropic itself. Partners receive access to Claude Mythos Preview to scan their codebases for vulnerabilities focused on local vulnerability detection, black-box binary testing, endpoint security and penetration testing.

Anthropic committed USD 100 million in Claude Mythos Preview usage credits to the programme. An additional USD 4 million in cash donations was distributed to open-source security organisations USD 2.5 million to the Alpha-Omega project and the Open Source Security Foundation under the Linux Foundation and USD 1.5 million to the Apache Software Foundation.

On June 2, Anthropic expanded the programme to approximately 150 new organisations across more than 15 countries bringing the total coalition to roughly 200. The selection criteria were strict. Each new entrant had to provide critical infrastructure where a successful compromise would affect more than 100 million people. The sectors covered include power, water, healthcare, communications and hardware.

What Claude Mythos Preview Actually Does

Unlike standard vulnerability scanners that rely on signature matching or static analysis, Mythos Preview operates as an autonomous agent. It reads source code or binary structures inside a secure container isolated from the internet, formulates specific vulnerability hypotheses, compiles and runs the programme and uses custom debuggers to verify whether a flaw is reachable and exploitable. If it is the model attempts to build a working proof-of-concept exploit.

The results from the first phase of the programme were significant. Claude Mythos Preview found a 27-year-old integer overflow vulnerability in OpenBSD, a 16-year-old vulnerability in FFmpeg that automated fuzzing engines had executed over five million times without detecting and a 17-year-old remote code execution vulnerability in FreeBSD triaged as CVE-2026-4747 that granted unauthenticated attackers full root access to systems running NFS services. It also found a critical certificate forgery vulnerability in wolfSSL, assigned CVE-2026-5194 with a CVSS score of 9.1, which allowed attackers to forge certificates and impersonate legitimate financial or communications entities.

Across the 50 founding partner organisations, the programme surfaced more than 10,000 high or critical severity vulnerabilities within the first month.

The Problem the Numbers Reveal

Finding vulnerabilities at machine speed has exposed a structural mismatch in how cybersecurity actually works. Discovery is now fast and scalable. Remediation is still slow and human. Of more than 6,200 potential vulnerabilities flagged in open-source projects scanned by the programme only 1,596 had been disclosed to maintainers by May 22. Of those, 88 had been formally acknowledged with a CVE or GHSA designation and approximately 97 had been patched upstream roughly 6 percent of flagged issues.

Jim Sherlock, Vice President of AI and Cybersecurity R&D at ProCircular, put the operational pressure plainly: “My advice is to spend about five minutes processing Anthropic’s latest announcement and then immediately get back to looking at your own patch cycle, because that is where companies are going to get burned. Expect the next wave of security advisories to come from your vendors, in volume, faster than your change windows were built to handle.”

The median timeline for threat actors to weaponise a publicly disclosed CVE has dropped from over two years in 2018 to single-digit hours today. Twenty-eight percent of vulnerabilities are now exploited within 24 hours of public disclosure. When AI can find them in hours, the 90-day coordinated disclosure standard is under significant stress.

The Export Control Order That Changed Everything

On June 9, Anthropic launched Claude Fable 5 as a publicly accessible version of the Mythos-class architecture with conservative safety filters, and simultaneously upgraded Glasswing partners to Claude Mythos 5. Three days later on June 12, the US Department of Commerce issued a directive ordering Anthropic to immediately suspend access to both models for any foreign national, whether located inside or outside the United States. The order applied to Anthropic’s own non-US employees as well.

Because filtering users reliably by nationality was technically unfeasible at the API and infrastructure level, Anthropic disabled both Fable 5 and Mythos 5 for all customers worldwide. The trigger according to reports, was a narrow jailbreak of Fable 5 flagged by Amazon researchers that allowed users to bypass safety filters through a software debugging prompt. (Read More On This: https://beatsinbrief.com/2026/06/13/us-ai-export-controls-fable-5-shutdown-india-sovereignty/)

What This Means for India

The export order landed at a significant moment for Anthropic’s India presence. The company had opened a Bengaluru office in February 2026, and its Indian run-rate revenue had doubled since. Anthropic had established a strategic partnership with TCS to deploy Claude internally across more than 50,000 employees. India had been described by the company as its second-largest market globally.

Under the Glasswing expansion a small cohort of Indian entities including public sector infrastructure agencies, telecom operators and CERT-In had been in the process of gaining access to Mythos Preview for sovereign codebase security. The June 12 directive locked them out immediately.

For Indian IT majors like TCS, Infosys and Wipro, who manage legacy codebases for multinational corporations globally the asymmetry is a practical problem. US-based competitors with continued access to specialised defensive models can validate and patch software in hours. Indian firms without that access must rely on manual security audits or filtered, lower-capability public models. Geopolitical policy analyst Subimal Bhattacharjee argues the episode proves that frontier AI models are no longer being treated as commercial software they are now subject to the same export control logic as strategic hardware. The immediate response within India’s technology sector has been an accelerated push toward sovereign AI development and open-source model fine-tuning as an alternative.

About the Author

Dipanshu Chaturvedi's avatar

Dipanshu Chaturvedi

Author

Dipanshu Chaturvedi is a writer at Beats in Brief, covering contemporary issues across current affairs. He has interests in geopolitics, the economy, and technology, and focuses on emerging trends and policy developments. His work emphasizes clarity, depth, and critical insight.

View All Posts

Post navigation

Previous: India’s Homegrown Chip Dream: iVP Semi Proposes Mature-Node Fab in Coimbatore
Next: SpaceX To Acquire Cursor’s Parent Anysphere for $60 Billion

Recent Posts

  • BRICS and the Dollar Dilemma: Why Linking Payment Systems Is Easier Than Replacing the Greenback
  • Inside Global Fintech Fest 2026: India Rolled Out Tokenised Bonds, AI Agents and a New “Know Your Agent” Debate
  • iPhone 18 Pro Hits India at ₹1,64,900 With a New Chip, Camera and 45-Hour Battery: Everything You Need to Know
  • India’s Tech Ecosystem Gets a Global Spotlight at Apple’s Latest Event
  • ISRO Just Tested a More Powerful CE20 Engine: Here’s What It Means for LVM3

ALSO READ

2698-50kb
  • Economy
  • Geopolitics

BRICS and the Dollar Dilemma: Why Linking Payment Systems Is Easier Than Replacing the Greenback

Himanshu Pandey September 11, 2026
Global Fintech Fest 2026
  • Tech
  • Business

Inside Global Fintech Fest 2026: India Rolled Out Tokenised Bonds, AI Agents and a New “Know Your Agent” Debate

Dipanshu Chaturvedi September 11, 2026
iPhone 18 fold india
  • Tech
  • Business

iPhone 18 Pro Hits India at ₹1,64,900 With a New Chip, Camera and 45-Hour Battery: Everything You Need to Know

Dipanshu Chaturvedi September 11, 2026
2690-50kb
  • Tech

India’s Tech Ecosystem Gets a Global Spotlight at Apple’s Latest Event

Himanshu Pandey September 11, 2026
  • Opinion
  • Geopolitics
  • Economy
  • Explainers
  • Tech
  • Business
  • Defence
  • Infrastructure
  • All Posts
  • About Us
  • Terms & Conditions
  • Editorial Policy
  • Privacy Policy
  • Contact Us
  • About Us
  • Articles
  • Beats in Brief
  • Contact Us
  • Disclaimer
  • Editorial Policy
  • Privacy Policy
  • Terms & Conditions
MoreNews by AF themes.